Research
Enclave finds five unexpected attack routes in DeepSeek V4.1 Flash tests
Enclave reports that DeepSeek V4.1 Flash achieved an 11/11 result in its hacking evaluation. Its audit identified six planned exploits and five unexpected routes, raising a concrete question about what an aggregate success score measures.
Key points
- Enclave reports an 11/11 result for DeepSeek V4.1 Flash.
- The audit confirmed six exploits that followed planned routes.
- Five other routes were unexpected, according to Enclave's account.
Why it matters
Teams choosing models for security testing need to inspect how tasks were completed. A success count alone does not show whether an agent exercised the intended capability or found another way through the environment.
What to watch
The next useful evidence is a task-level account of the five unexpected routes, including whether they represent valid exploits and whether other evaluators reproduce the results.
Sources
- enclave.ai2026-09-16 · Global source